VYPR

Vendor CVEs

1panel Dev

All CVEs

61 total · sorted by risk
  • CVE-2026-6107LowApr 12, 2026
    risk 0.16cvss 3.5epss 0.00

    A flaw has been found in 1Panel-dev MaxKB up to 2.6.1. This issue affects some unknown processing of the file apps/common/middleware/chat_headers_middleware.py of the component ChatHeadersMiddleware. This manipulation of the argument Name causes cross site scripting. Remote…

  • CVE-2026-6106LowApr 11, 2026
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was detected in 1Panel-dev MaxKB up to 2.2.1. This vulnerability affects the function StaticHeadersMiddleware of the file apps/common/middleware/static_headers_middleware.py of the component Public Chat Interface. The manipulation of the argument Name results in…

  • CVE-2026-39419LowApr 14, 2026
    risk 0.13cvss 3.1epss 0.00

    MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an authenticated user can bypass sandbox result validation and spoof tool execution results by exploiting Python frame introspection to read the wrapper's UUID from its bytecode constants, then…

  • CVE-2026-10514LowJun 2, 2026
    risk 0.09cvss 2.4epss 0.00

    A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function of the file backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java. The manipulation leads to cross site scripting. Remote exploitation of the attack is…

  • CVE-2026-16223MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function getSqlBotSrc of the file backend/crm/src/main/java/cn/cordys/crm/system/service/IntegrationConfigService.java of the component Third Party Edit Endpoint. Executing a manipulation of the…

  • CVE-2026-16222MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java of the component Third Party Endpoint. Performing a manipulation of the…

  • CVE-2026-54149HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.00

    MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/serializers/tool.py and MCP referencing mode in apps/application/chat_pipeline/step/chat_step/impl/base_chat_step.py do not consistently validate MCP transport…

  • CVE-2026-56779MedJun 25, 2026
    risk 0.00cvss 6.4epss 0.00

    MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to make arbitrary server requests by supplying unvalidated downloadCallbackUrl and download_url parameters. Attackers with default…

  • CVE-2025-66419HigDec 11, 2025
    risk 0.00cvss 8.8epss 0.00

    MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0.

  • CVE-2025-48950HigJun 3, 2025
    risk 0.00cvss 8.8epss 0.00

    MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common directories, such as `/bin,/usr/bin`, etc. Therefore, attackers can exploit some files with execution permissions in non…

  • CVE-2025-32383MedApr 10, 2025
    risk 0.00cvss 4.3epss 0.00

    MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). A reverse shell vulnerability exists in the module of function library. The vulnerability allow privileged‌ users to…

Page 2 of 2